CVE-2024-36555

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 6, 2025
Updated: Feb 10, 2025
CWE ID 306

Summary

CVE-2024-36555 is a vulnerability affecting the Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b devices. Malicious users can exploit this issue by manipulating a built-in SMS-configuration command to alter the device's IMEI number. This vulnerability enables attackers to forge the identity of the device, potentially gaining unauthorized access or impersonating the targeted device. This issue poses a significant risk to user privacy and security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share